Google Used AI to Find and Fix a Huge Number of Chrome Security Flaws

Google announced on July 30, 2026 that it fixed more security bugs in its Chrome browser during June 2026 than in the preceding two years combined. The company says AI tools made this possible (TechCrunch).
The numbers are striking. Chrome versions 149 and 150, both released in June 2026, collectively addressed 1,072 security vulnerabilities. By comparison, the previous 23 Chrome releases going back to June 2024 patched 1,036 bugs in total (TechCrunch). In other words, two updates in a single month fixed more problems than nearly two years of prior updates combined.
Chrome 149 shipped on June 12, 2026 (Google Chrome Enterprise support). It alone patched 429 security vulnerabilities, 22 of them rated critical (Forbes). Chrome 150, also released in June, accounted for the remainder of the 1,072.
A security vulnerability is a flaw in software that attackers could use to cause harm, such as stealing data or taking control of a system. A patch is the fix that closes that flaw. Google says AI models like Gemini can now scan Chrome's code, find these flaws, and help fix them before attackers get the chance to exploit them. Doug Turner, Chrome's director of engineering, described this approach to TechCrunch, and Google published a white paper with more detail (TechCrunch; Google Security Blog).
Google is not alone in this trend. Microsoft announced in July 2026 that it patched a record 570 security vulnerabilities across its products in a single monthly update cycle, also citing its use of AI (TechCrunch). Apple, by an independent count maintained on GitHub by Proteas, patched 482 bugs in 2026 (TechCrunch).
The broader context is that all three major technology companies are now reporting much higher patch counts, and all three connect those numbers to AI. But a spike in patched bugs can mean two different things. It could mean AI is catching flaws that humans and older tools simply missed — a genuine improvement in safety. Or it could mean the software has the same number of flaws as before, and the tools are just finding and reporting them faster. The numbers alone cannot tell us which explanation is correct. Google's comments and white paper lean toward the first view.
There is also a gap worth noting between the number of patches and how much safer users actually are. Chrome 149's 429 fixes included 22 rated critical, meaning they were serious enough that attackers could have done real damage. But the severity breakdown for Chrome 150 has not been publicly itemized. Without knowing how serious each of the 1,072 fixes was, it is hard to tell how many addressed truly dangerous flaws versus minor ones. We also do not know whether any of these bugs were being actively exploited by attackers at the time they were fixed.
The announcement also leaves open a practical question. Shipping hundreds of fixes in a single update means those fixes need to be tested to make sure they do not break anything else. Google has not publicly discussed how its AI workflow handles that testing, and the available sources do not mention false positives — cases where the AI flagged a problem that turned out not to be real. For IT teams that manage large numbers of computers, the workload of reviewing and installing these updates is growing regardless of whether the software is getting safer.
The optimistic view, which is the one Google's framing points toward, is simple: flaws that would have sat hidden in the software for months or years are being found and fixed before attackers can use them. If that is what is happening, the result is a browser running on billions of devices with fewer weaknesses for criminals to target. That would be a genuine and compounding improvement.
The cautionary note is that the number of patches tells us how good the search tools have become, not necessarily how good the software is. The next several months of updates will show whether June's 1,072 fixes were a one-time catch-up as the AI tools came online, or a new normal. Either way, AI-assisted security checking for everyday consumer software has clearly arrived, and the biggest tech companies are now competing publicly on how many flaws they can find in their own products.

